Re: Dovecot's default password storage scheme is not GDPR compliant

2025-02-12 Thread Michael Slusarz via dovecot
GDPR applies to companies operating software, not the software itself. As Aki pointed out (somewhere) in this thread, Dovecot doesn't store passwords itself, and doesn't work unless an admin proactively configures at least one authentication mechanism, so it is "secure by default" under any defi

Re: Dovecot's default password storage scheme is not GDPR compliant

2025-02-12 Thread infoomatic via dovecot
On 12.02.25 01:25, Steven Varco via dovecot wrote: So, after my mandatory rant :D, the DEFAULT setup of dovecot should actually be as simple as possible. I fully second that. There is no need to discuss whether dovecots default password storage complies to GDPR or not. The administrator or

RE: Dovecot's default password storage scheme is not GDPR compliant

2025-02-12 Thread Marc via dovecot
> > > Therefore, Dovecot's plain text default, and the md5 option, are both > non-GDPR compliant. > > > > To avoid monetary sanctions, Dovecot ought to change how it stores > passwords by default. > > > > Please do not ignore this message. > > GDPR is some piece of bull*it regulation made by th

Re: Dovecot's default password storage scheme is not GDPR compliant

2025-02-11 Thread Steven Varco via dovecot
> Therefore, Dovecot's plain text default, and the md5 option, are both > non-GDPR compliant. > > To avoid monetary sanctions, Dovecot ought to change how it stores passwords > by default. > > Please do not ignore this message. GDPR is some piece of bull*it regulation made by the EU. Dovecot

Re: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Aki Tuomi via dovecot
  On 10/02/2025 20:36 EET Kent Borg via dovecot wrote:     On 2/10/25 5:07 AM, Robert Nowotny via dovecot wrote: >> A default dovecot (el9 rpm) install is compliant as it does not work >> and does not do anything, it is just a bunch of binaries on a dis

Re: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Kent Borg via dovecot
On 2/10/25 5:07 AM, Robert Nowotny via dovecot wrote: A default dovecot (el9 rpm) install is compliant as it does not work and does not do anything, it is just a bunch of binaries on a disk. and how exactly this answer is useful ? oh my, I am feeding the troll again I see it as a useful

Re: RE: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Aki Tuomi via dovecot
SCRAM-SHA-256/512 could be one. Aki > On 10/02/2025 16:13 EET Jochen Bern via dovecot wrote: > > > On 10.02.25 14:18, Aki Tuomi wrote: > > I am not sure how we should actually implement this. Do you mean > > that we should require that you always provide a password scheme > > for credentials,

Re: RE: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Jochen Bern via dovecot
On 10.02.25 14:18, Aki Tuomi wrote: I am not sure how we should actually implement this. Do you mean that we should require that you always provide a password scheme for credentials, or require explicit {PLAIN} prefix or what? Everything costs something and has unexpected side-effects, like break

Re: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread José Celestino via dovecot
> On 10 Feb 2025, at 10:23, Rupert Gallagher via dovecot > wrote: > > Dovecot aligns the password encryption scheme used by the imap client with > the password storage scheme used by the server. > > Since the default is set to plain text, the client sends the password in > plain text (tls tun

RE: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Aki Tuomi via dovecot
Von:* Rupert Gallagher via dovecot > > *Gesendet:* Montag, 10. Februar 2025 um 13:51 MEZ > > *An:* aki.tu...@open-xchange.com > > *Kopie:* dovecot > > *Betreff:* RE: Dovecot's default password storage scheme is not GDPR > compliant > > > > I do, Aki.

RE: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Marc via dovecot
Your argument is "that a default install is not compliant" and therefore you ask people to change things. I am proving your argument is incorrect, so the basis of your change request is gone. > > A default dovecot (el9 rpm) install is compliant as it does not work > and does not do anything, i

RE: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Robert Nowotny via dovecot
13:56 MEZ *An:* Rupert Gallagher , aki.tu...@open-xchange.com *Kopie:* dovecot *Betreff:* RE: Dovecot's default password storage scheme is not GDPR compliant This is not the point, however. The point is that the default is not GDPR compliant, and a first easy alternative is als

RE: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Robert Nowotny via dovecot
: Dovecot's default password storage scheme is not GDPR compliant I do, Aki. This is not the point, however. The point is that the default is not GDPR compliant, and a first easy alternative is also not GDPR compliant, and decoupling the user scheme from the server storage scheme is not a

RE: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Marc via dovecot
> > This is not the point, however. > > The point is that the default is not GDPR compliant, and a first easy > alternative is also not GDPR compliant, and decoupling the user scheme > from the server storage scheme is not at all obvious. Adopting a GDPR- > compliant default would send out the in

Re: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Rupert Gallagher via dovecot
I do, Aki. This is not the point, however. The point is that the default is not GDPR compliant, and a first easy alternative is also not GDPR compliant, and decoupling the user scheme from the server storage scheme is not at all obvious. Adopting a GDPR-compliant default would send out the in

Re: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Aki Tuomi via dovecot
> On 10/02/2025 12:23 EET Rupert Gallagher via dovecot > wrote: > > > Dovecot aligns the password encryption scheme used by the imap client with > the password storage scheme used by the server. > > Since the default is set to plain text, the client sends the password in > plain text (tl

RE: Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Marc via dovecot
> > Dovecot aligns the password encryption scheme used by the imap client > with the password storage scheme used by the server. > > Since the default is set to plain text, the client sends the password in > plain text (tls tunneled), and the server local storage of passwords is > a plain text fi

Dovecot's default password storage scheme is not GDPR compliant

2025-02-10 Thread Rupert Gallagher via dovecot
Dovecot aligns the password encryption scheme used by the imap client with the password storage scheme used by the server. Since the default is set to plain text, the client sends the password in plain text (tls tunneled), and the server local storage of passwords is a plain text file. For m